s2
--:--:--UTC

Searching APEX

Starting…

  1. ○ Searching Threats, IOCs & Threat Intelligence locally
  2. ○ Querying external providers
  3. ○ Asking AI Forensic Validator
  4. ○ Creating new entry from validated hit

0s elapsed

TF-1850352 high

📛 Threat Title

RevStealer: Domain that is used for botnet Command&control (C&C) deploy.works-rhythm8.click

Category: RevStealer Published: Source updated: First seen: Last updated: Source: ThreatFox IOCs

Description

Indicator that identifies a botnet command&control server (C&C). IOC type: Domain that is used for botnet Command&control (C&C). Attributed malware: RevStealer. Confidence: 100. First seen: 2026-07-14 14:44:15 UTC. Reporter: Myrtus0x0. Tags: exe, RevStealer.

Indicators of Compromise (3)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

ipv4 104.21.28.109

IOC database

Type
ipv4
Value
104.21.28.109
First seen
Last seen
Attached to this threat
Appears in
2 threats
Description
Resolved from domain deploy.works-rhythm8.click

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

ipv4 172.67.145.220

IOC database

Type
ipv4
Value
172.67.145.220
First seen
Last seen
Attached to this threat
Appears in
2 threats
Description
Resolved from domain deploy.works-rhythm8.click

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

domain deploy.works-rhythm8.click UrlVoid 3 / 35

IOC database

Type
domain
Value
deploy.works-rhythm8.click
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
Ingested from IOC source: https://threatfox.abuse.ch/downloads/hostfile/

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

References (3)

  • Malpedia profile ThreatFox IOCs
  • ThreatFox IOC page ThreatFox IOCs

    Indicator that identifies a botnet command&control server (C&C). IOC type: Domain that is used for botnet Command&control (C&C). Attributed malware: RevStealer. Confidence: 100. First seen: 2026-07-14 14:44:15 UTC. Reporter: Myrtus0x0. Tags: exe, RevStealer.

  • External reference ThreatFox IOCs

Remediations (10)

  • web:blog.pulsedive.com

    Dive into a technical primer on the modern botnet landscape - including the evolution of Mirai-based botnets , capabilities, and recent enforcement actions.

  • web:clickpatrol.com

    DNS sinkholing is a clever technique to disrupt botnet communication by rerouting traffic that typically goes to a Command and Control server. How it works: A sinkhole server mimics a legitimate DNS server. When a bot-infected machine tries to contact its C2 domain , it is silently rerouted to the sinkhole.

  • web:help.bitsighttech.com

    ⇤ Compromised Systems Findings The Botnet Infections risk vector is an indication of a host participating in a botnet , including active bots and Command and Control servers ( C&C servers). Navi...

  • web:networkthreatdetection.com

    Learn how recognizing botnet command and control patterns reveals hidden threats and keeps your network safe from malicious attacks.

  • web:threatfox.abuse.ch

    RevStealer IOC: deploy.works-rhythm8.click ( domain ) You are viewing the ThreatFox database entry for domain deploy.works-rhythm8.click.

  • web:www.bsi.bund.de

    Current bot overviews This page is designed to give you an overview of the most common botnet families currently in existence. We provide a summary of the type of infection, the systems affected and what action you can take to clean up your system. The list is non-exhaustive and is being updated all the time.

  • web:www.geeksforgeeks.org

    At this point, the infected devices are connected and controlled remotely through a central command-and-control (C&C) server. The attacker can command these devices, to perform tasks like sending spam, participating in distributed denial-of-service (DDoS) attacks, or stealing data. How to Prevent Botnet Attacks?

  • web:www.radware.com

    Botnet detection involves identifying networks of infected computers controlled by attackers to perform malicious activities. Early detection can prevent substantial damage to systems and networks, requiring techniques to monitor and analyze behavior patterns, traffic anomalies, and communication protocols.

  • web:www.spamhaus.org

    Overall botnet command control (C&C) activity decreased marginally by -4% between July and December last year. China dominated the Top 20 charts with increased botnet C&C activity across domain registrars and networks, ranking #1 globally for hosting botnet C&C servers. Download the latest report to learn more.

  • web:www.spamhaus.org

    Once active, it can execute commands, steal data, deploy additional malware, and maintain persistence through scheduled tasks and encrypted communication with its command-and-control servers.

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.

VirusTotal Information

loading…

IP Geolocation

Loading…